crystal (1.21.0+dfsg-1) unstable; urgency=medium . * New upstream version. * Build with LLVM 21 (Closes: #1124047). * Update disable-udp-multicast-specs patch to disable internet facing specs (Closes: #1137045). * Update standards version; no changes needed. * Align manpages with new manuals. django-prometheus (2.5.0-2) unstable; urgency=medium . * Team upload. * Only use postgis in autopkgtests on architectures where it exists (closes: #1144042). django-prometheus (2.5.0-1) unstable; urgency=low . * New upstream version 2.5.0 * Use uscan version 5 GitHub template. * Drop field Priority: optional. * Use dh-sequence-python3. * Set debhelper compatibility to 14. * Bump Standards-Version to 4.7.4. * Drop Rules-Requires-Root. * Update year in d/copyright. * Switch Testsuite to autopkgtest-pkg-pybuild. * Remove '--with python3' from dh call, already implied by dh-sequence-python3. * Set X-Style: black and reformat. * Make almost all DB wrapper tests also run in autopkgtest. rsync (3.5.0+ds1-2) unstable; urgency=medium . * d/rsync.NEWS: Fix date in latest entry * d/p/testsuite_make_basis_xname...: Pull patch to fix the hurd-i386 FTBFS * d/p/testsuite_interpose_lfs...: New patch to fix the i386 and alpha FTBFS * d/p/testsuite_punch_granularity...: New patch to fix the loong64 FTBFS rsync (3.5.0+ds1-1) unstable; urgency=medium . [ Sylvain Beucler ] * autopkgtest improvements * Drop allow-stderr autopkgtest restriction . [ Samuel Henrique ] * New upstream version 3.5.0+ds1, fixing 33 CVEs: - CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) - CVE-2026-53784: Daemon module-root chdir escape under "use chroot = no" - CVE-2026-53785: --relative implied-parent creation escapes the destination tree - CVE-2026-53786: Daemon --filter merge file bypasses the module filter list - CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol - CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent - CVE-2026-53790: Command / argument injection via unquoted peer- or host-controlled values - CVE-2026-53791: PROXY-protocol mode lets a direct client spoof the daemon's source address - CVE-2026-53792: Receiver-supplied zero checksum block length drives sender matching negative - CVE-2026-53793: Chroot "/./" inner-module escape via a parent-component symlink - CVE-2026-53794: Remote peer disables the per-allocation sanity cap via --max-alloc=0 - CVE-2026-53795: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement - CVE-2026-53796: Non-daemon receiver destination-chdir symlink race (TOCTOU) - CVE-2026-53797: Sender source-tree parent-component symlink race -> out-of-tree disclosure - CVE-2026-53798: Daemon name-converter empty response maps an unknown name to uid/gid 0 - CVE-2026-53799: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege escalation) - CVE-2026-53800: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion outside the source tree - CVE-2026-53801: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure - CVE-2026-53802: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files - CVE-2026-53803: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths - CVE-2026-70452: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block - CVE-2026-70453: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain - CVE-2026-70454: rsync-ssl establishes an unauthenticated TLS connection (no CA verification; no stunnel hostname binding) - CVE-2026-70455: Peer-controlled Zstandard worker exhaustion on an rsync daemon - CVE-2026-70456: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs - CVE-2026-70457: Attacker-chosen-offset write in parse_size_arg() error formatting - CVE-2026-70458: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H - CVE-2026-70459: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root - CVE-2026-70460: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in-module symlink - CVE-2026-70461: Peer-driven one-byte heap out-of-bounds write in add_implied_include() - CVE-2026-70462: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (signed overflow, and a non-positive value) - CVE-2026-70463: "auth users" ignores documented comma-only parsing, silently skipping a deny/read-only rule - CVE-2026-70464: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module * d/p/skip_devices_test_non_linux.patch: Drop patch applied upstream * d/patches: - Pull 3 patches for regression fixes: ~ Honor_STRIP_in_install-strip_for_cross-compilation.patch ~ rrsync_support_fd_pins_in_user_namespaces.patch ~ testsuite_bound_the_unshare_probe.patch * d/rsync.NEWS: Add a NEWS entry about all the behavior changes rust-ed25519 (3.0.0-1) unstable; urgency=medium . * Package ed25519 3.0.0 from crates.io using debcargo 2.8.3 * Move package maintenance to the Debian Rust Team. Thanks to Jonas Smedegaard for introducing this package to Debian and maintaining it since 2023. rust-pkcs5 (0.8.1-1) unstable; urgency=medium . * Team upload. * Package pkcs5 0.8.1 from crates.io using debcargo 2.8.3 rust-pkcs8 (0.11.0-1) unstable; urgency=medium . * Package pkcs8 0.11.0 from crates.io using debcargo 2.8.3 * Move package maintenance to the Debian Rust Team. Thanks to Jonas Smedegaard for introducing this package to Debian and maintaining it since 2023. rust-spki (0.8.0-1) unstable; urgency=medium . * Team upload. * Package spki 0.8.0 from crates.io using debcargo 2.8.3